Man-in-the-middle attack in IBM Corporation products - CVE-2018-1454
Published: June 5, 2018
Vulnerability identifier: #VU13184
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2018-1454
CWE-ID: CWE-300
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: IBM Corporation
Affected software:
IBM InfoSphere Information Governance Catalog
IBM InfoSphere Data Click
IBM InfoSphere Information Server for Cloud
IBM InfoSphere Information Governance Catalog
IBM InfoSphere Data Click
IBM InfoSphere Information Server for Cloud
Detailed vulnerability description
The vulnerability allows a remote attacker to conduct man-in-the-middle attack.
The vulnerability exists due to system does not properly enable HTTP Strict Transport Security. A remote attacker can conduct man-in-the-middle attack, intercept of the communication channel between the affected app and access arbitrary data.
How to mitigate CVE-2018-1454
Install update from vendor's website.